---
title: Idira Endpoint Privilege Manager by Palo Alto Networks
description: Gain insights into Idira Endpoint Privilege Manager logs
breadcrumbs: Docs > Integrations > Idira Endpoint Privilege Manager by Palo Alto Networks
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Idira Endpoint Privilege Manager by Palo Alto Networks
Supported OS Integration version1.0.0
{% callout %}
# Important note for users on the following Datadog sites: us2.ddog-gov.com

{% alert level="info" %}
To find out if this integration is available in your organization, see your [Datadog Integrations](https://app.datadoghq.com/integrations) page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [support@ddog-gov.com](mailto:support@ddog-gov.com).
{% /alert %}

{% /callout %}
            Idira EPM OverviewIdira EPM OverviewIdira EPM Raw EventsIdira EPM Raw EventsIdira EPM Policy Audit EventsIdira EPM Policy Audit EventsIdira EPM Set & Account Admin ActivitiesIdira EPM Set & Account Admin Activities
## Overview{% #overview %}

[Idira Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager) enforces least privilege and enables organizations to block and contain attacks on endpoint computers, reducing the risk of information being stolen or encrypted and held for ransom.

This integration ingests the following logs:

- **Raw Events**: Endpoint activities captured by EPM agents, including threat detection events.
- **Policy Audit Events**: Audit records of policy usage on endpoints.
- **Set Admin Audit Events**: Actions carried out by EPM administrators within sets.
- **Account Admin Audit Events**: Actions performed by account administrators.

Integrate Idira Endpoint Privilege Manager with Datadog to gain insights into raw events, policy audit events, set admin audit events, and account admin audit events using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.

## Setup{% #setup %}

### Create a Role and Assign a User in Idira Endpoint Privilege Manager{% #create-a-role-and-assign-a-user-in-idira-endpoint-privilege-manager %}

1. Log in to the Idira Endpoint Privilege Manager portal and navigate to **Administration**.
1. Open the **Roles** section and click **Create role**.
1. Enter the role details:
   - **Name**: Name of the role (e.g., *View Only Set Admin Role*)
   - **Permission groups**: Select `View Only Set Admin`
   - **Sets**: Select the required sets to collect data

1. Click **Create**.
1. Open the **Users** section and click **Add user**.
1. Enter the user details:
   - **User email**, **Password**, and **Confirm password**

1. Click **Add**.
A verification email is sent to the provided address. The user must open the email and click the verification link to activate the account before proceeding.

1. Open the **Role assignment** section, locate the newly created role, and click **Assign or unassign users** from its options menu.
1. Click **Assign users**, select the newly created user's email, click **Assign**.
1. Click **Save**.
1. Locate the **Account Admin ViewOnly Role**, and click **Assign or unassign users** from its options menu.
1. Click **Assign users**, select the newly created user's email, click **Assign**.
1. Click **Save**.

### Connect your Idira Endpoint Privilege Manager Account to Datadog{% #connect-your-idira-endpoint-privilege-manager-account-to-datadog %}

1. Add your `EPM Account Region`, `Username`, and `Password`.
| Parameters         | Description                                                                                      |
| ------------------ | ------------------------------------------------------------------------------------------------ |
| EPM Account Region | The EPM Account Region of your Idira Endpoint Privilege Manager.                                 |
| Username           | The Username of Idira Endpoint Privilege Manager account which has access to the available sets. |
| Password           | The Idira Endpoint Privilege Manager account password.                                           |
1. Click **Save**.

## Data Collected{% #data-collected %}

The Idira Endpoint Privilege Manager integration collects and forwards raw events, policy audit events, set admin audit events, and account admin audit events to Datadog.

### Metrics{% #metrics %}

The Idira Endpoint Privilege Manager integration does not include any metrics.

### Events{% #events %}

The Idira Endpoint Privilege Manager integration does not include any events.

## Troubleshooting{% #troubleshooting %}

Need help? Contact [Datadog support](https://docs.datadoghq.com/help/).
